Standards
Authoritative references from ISO, IEEE, and others, grouped by category and linked to the qualities they back.
Category
Organization
AIUC-1 – AI Agent Standard
Commercial framework for enterprise AI agent adoption, addressing data and privacy, security, safety, reliability, accountability, and societal risk.
EU Cyber Resilience Act (CRA) — Regulation 2024/2847
EU regulation mandating cybersecurity requirements for products with digital elements across their lifecycle: secure-by-design, vulnerability handling, updates.
DICOM — Digital Imaging and Communications in Medicine
International standard for storing, transmitting, and managing medical imaging data across modalities, PACS, and viewers for cross-vendor interoperability.
DO-178C - Software Considerations in Airborne Systems and Equipment Certification
The de facto standard for developing and certifying airborne software, defining objective-based assurance levels (DAL A-E) tied to system safety impact.
EN 301 549 - Accessibility requirements for ICT products and services
European standard defining accessibility requirements for ICT products and services across the EU: web, software, hardware, telecoms, and documents.
ETSI EN 304 223 - AI Cybersecurity Baseline Requirements
European standard setting baseline cybersecurity requirements for AI models and systems across their lifecycle, complementing the EU AI Act.
GDPR - General Data Protection Regulation
EU regulation governing the processing of personal data: individual rights, accountability, and privacy by design for anyone handling EU residents' data.
HL7 — Health Level Seven International (V2, CDA, FHIR)
Family of healthcare interoperability standards (V2, CDA, FHIR) for exchanging, integrating, and retrieving health information across organizations.
IEC 61508 - Functional safety of E/E/PE safety-related systems
Foundational cross-industry standard for functional safety of E/E/PE systems, built on a risk-based lifecycle and Safety Integrity Levels (SIL 1 to 4).
IEC 62304 - Medical device software
International standard defining software life cycle processes for medical device software, including standalone Software as a Medical Device (SaMD).
IEC 62443 - Security for Industrial Automation and Control Systems
Series of standards for cybersecurity of industrial automation and control systems, spanning product development, system integration, and operation.
IEEE 2857 - Privacy Engineering Guidelines
IEEE guidelines for engineering privacy into software and systems across the development lifecycle, translating privacy-by-design into technical practice.
IEEE 7000-2021 — Ethical Concerns in System Design
IEEE process for embedding ethical values into system design via value-based engineering: value elicitation, ethical risk assessment, and traceability.
IHE — Integrating the Healthcare Enterprise
Healthcare initiative defining integration profiles that combine HL7 and DICOM to solve interoperability problems, verified through Connectathon testing.
ISO/IEC 15408 - Common Criteria for IT Security
The Common Criteria framework for evaluating IT product security via protection profiles, security targets, and Evaluation Assurance Levels EAL1 to EAL7.
ISO 26262 - Road vehicles — Functional safety
Automotive functional-safety standard for electrical and electronic systems, defining a risk-based safety lifecycle and ASIL A to D risk classification.
ISO 8000 — Data Quality
International standard series for data quality and master data: defining, measuring, verifying, and exchanging quality data across sectors and systems.
ISO/IEC 12792 - AI transparency taxonomy
Taxonomy of information elements helping AI stakeholders identify and address the transparency needs of AI systems across model, data, and governance.
ISO/IEC 14756 - Measurement and Rating of Performance of Computer-Based Software Systems
Methods for measuring and rating user-oriented performance of computer-based software systems from the user's perspective: response times and throughput.
ISO/IEC 22989 - AI concepts and terminology
Foundational vocabulary for artificial intelligence: core concepts and terms for AI systems, data, lifecycle stages, roles, and AI properties.
ISO/IEC 25010 - Systems and Software Quality
The SQuaRE product quality model defining nine characteristics, from functional suitability and performance to security, maintainability, and safety.
ISO/IEC 25012 - Data Quality Model
SQuaRE-family data quality model defining 15 data quality characteristics across inherent and system-dependent perspectives for information systems.
ISO/IEC 25019 - Quality-in-use model
The SQuaRE quality-in-use model describing the outcome of system use through three characteristics: beneficialness, freedom from risk, and acceptability.
ISO/IEC 25022 - Measurement of quality in use
SQuaRE measures for quality in use: effectiveness, efficiency, satisfaction, freedom from risk, and context coverage in a specified context of use.
ISO/IEC 25024 - Measurement of Data Quality
SQuaRE measures for evaluating data quality characteristics such as accuracy, completeness, consistency, and timeliness across the data lifecycle.
ISO/IEC 27001 - Information security management
International standard specifying requirements for an information security management system (ISMS): risk-based establishment, operation, and improvement.
ISO/IEC 29100 - Privacy Framework
Privacy framework establishing common terminology, actors, and safeguards for processing personally identifiable information across its lifecycle.
ISO/IEC 38500 - Governance of IT for the Organization
International standard giving governing bodies principles for the effective, efficient, and acceptable use of IT via an Evaluate-Direct-Monitor model.
ISO/IEC 42001 - Artificial Intelligence Management System
International standard framing an AI management system (AIMS) to develop and use AI responsibly, with transparency, fairness, and accountability.
ISO/IEC 5055 - Automated Source Code Quality Measures
International standard defining four automated source-code quality measures for reliability, security, performance efficiency, and maintainability.
ISO/IEC TR 24028 - Overview of trustworthiness in artificial intelligence
Technical Report surveying trustworthiness in AI systems, cataloguing properties like reliability, robustness, safety, and fairness, plus AI threats.
ISO/IEC/IEEE 12207 - Software Life Cycle Processes
ISO/IEC/IEEE framework defining software life cycle processes across acquisition, development, operation, maintenance, and disposal of software systems.
ISO/IEC/IEEE 26514 - Design and Development of Information for Users
Requirements for designing and developing user information across the software lifecycle: planning, information architecture, writing, and presentation.
ISO/IEC/IEEE 29119 - Software Testing
International software testing standard series defining test processes, documentation, and techniques from small projects to regulated environments.
ISO/IEC/IEEE 42010 - Architecture Description
Framework for creating, evaluating, and comparing architecture descriptions using stakeholders, concerns, viewpoints, views, and documented decisions.
ISO/IEC/IEEE 42030 - Architecture Evaluation
Framework for systematically evaluating software, systems, and enterprise architectures: evaluation processes, methods, criteria, and quality models.
MISRA C - Guidelines for the use of the C language in critical systems
Guidelines defining a safer subset of the C language for safety- and security-critical embedded systems, reducing undefined behavior for higher assurance.
NIST AI RMF — Artificial Intelligence Risk Management Framework
NIST voluntary framework for managing AI risks across the system lifecycle, organized around seven trustworthiness characteristics and four functions.
NIST Privacy Framework — Managing Privacy Risk
NIST voluntary tool for managing privacy risk in personal data processing through enterprise risk management, organized around five core functions.
NIST SP 800-53 — Security and Privacy Controls
US catalog of security and privacy controls for information systems, providing a risk-based baseline for compliance and continuous monitoring.
OWASP Application Security Verification Standard (ASVS)
Open OWASP framework of requirement-level security controls for designing, building, and testing web applications and APIs, with three assurance levels.
PCI Data Security Standard (PCI DSS)
Payment card industry standard defining twelve baseline security requirements to protect cardholder data wherever it is stored, processed, or transmitted.
SOC 2 — Service Organization Control 2
AICPA auditing framework producing a CPA attestation report on a service organization's controls across five Trust Services Criteria.
SOX - Sarbanes-Oxley Act
US federal law mandating financial reporting accuracy and internal controls (ICFR) for systems that process, store, or report financial data.
WCAG 2.2 - Web Content Accessibility Guidelines
The W3C standard for web accessibility: how to make web content usable by people with disabilities, organized around the four POUR principles.
No standards match those filters.